Solved

the worm got me ....

Posted on 2001-07-30
8
190 Views
Last Modified: 2013-12-28
Windows98se, Norton SystemWorks 2001, last definition dated 7/25/01.  Norton's automatic system guard caught an infected c:\windows\system\SCan32.exe file with the w32.sircam.worm@mm.virus. The problem is that this file will not delete, will not repair, will not go away. I have renamed it, moved it, quarantined it and tried to repair it but it is still there - and will not allow the system to boot execpt into safe mode.    
Any ideas on how to get rid of this virus and go on with life?
0
Comment
Question by:waco
8 Comments
 
LVL 25

Expert Comment

by:dew_associates
ID: 6336569
Waco,

Here's a URL to the tool need to fix this:

http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.removal.tool.html

Dennis

PS: Here's some additional info from McAfee

http://dispatch.mcafee.com/dispatches/sir_cam/
0
 
LVL 2

Expert Comment

by:Adih
ID: 6337313
the tool dew referred you too attempts to delete the infected files and then removes all changes in registry and such, but note that after restart u should check for the file - if its there infected or if its missing,
run sfc from the command line to recover all lost/damaged system files.

i suspect this will also get rid of the infected file but be sure to run the program that u were referred to by dew in order to fix all damages.

good luck, adi.
0
 
LVL 14

Accepted Solution

by:
Don Thomson earned 200 total points
ID: 6337482
The SirCam Virus installs itsel;f in the system registry to load everytime you try and run an EXE  file. Load regedit (if it won't load - rename the regedit.exe to regedit.com first)

In the first group, HKEY_CLASSES_ROOT  goto exefile open to Shell/open/command  if the virus is stil active you will see the value as "C:\recycled\Sircam.exe""%1"%*
Change it to just "%1"%*

Close registry

This will stop it from executing every time you try and run anything. Make sure that the Recyled folder in no excluded in any of you Virus programs. Set Vscan to auto clean - not prompt or quarantine.

Then run SFC to check for damaged system files
0
 

Expert Comment

by:deroth
ID: 6337737
I also found an entry in the autoexec on several cases of this.   Be sure it is deleted from the autoexec if it is in there.  It was calling for the startup of sircam.exe as it does in the registry.   I also found the sfc repair was essential to get it totally cleaned out. Agree with all the above.
0
Do email signature updates give you a headache?

Constantly trying to correctly format email signatures? Spending all of your time at every user’s desk to make updates? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today!

 
LVL 18

Expert Comment

by:centerv
ID: 6338983
The tool did not work for me.  Win ME
Could not recognize that the restore option was shut down.

Did remove manually following procedure.

http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.html
0
 

Author Comment

by:waco
ID: 6347247
Thanks all - it gets worse. There may be a dual problem here, one with the virus and the other with Norton's System Works 2001. The system is halted during boot up by the Norton (DOS looking) screen warning of the attack and offering several choices, delete file, skip, quarantine, etc., but whatever option is chosen results in a blank black screen and a system freeze. I am now told that the floppie does not work so I cannot use the cure via a disk. I can however get into safe mode but cannot run the dial up from there to download. Is there a manual step_by_step procedure out there?
0
 

Author Comment

by:waco
ID: 6347273
Thanks all - it gets worse. There may be a dual problem here, one with the virus and the other with Norton's System Works 2001. The system is halted during boot up by the Norton (DOS looking) screen warning of the attack and offering several choices, delete file, skip, quarantine, etc., but whatever option is chosen results in a blank black screen and a system freeze. I am now told that the floppie does not work so I cannot use the cure via a disk. I can however get into safe mode but cannot run the dial up from there to download. Is there a manual step_by_step procedure out there?
0
 
LVL 18

Expert Comment

by:centerv
ID: 6350483
check the above link and scroll down to
MANUAL REMOVAL
0

Featured Post

Make managing Office 365 email signatures a breeze

Are you using Office 365? Having trouble trying to set up email signatures for your users? Getting stressed out managing multiple signatures? Need an easier way to manage? We have a solution for you, try the most-user friendly and powerful signature management tool on the market.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A Bare Metal Image backup allows for the restore of an entire system to a similar or dissimilar hardware. They are highly useful for migrations and disaster recovery. Bare Metal Image backups support Full and Incremental backups. Differential backup…
In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now